Qualcomm
Qualcomm Mdm9607 Firmware: vulnerabilidades y CVE
Qualcomm Mdm9607 Firmware tiene 736 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 263 son críticas y 2 figuran en el catálogo de explotación activa de CISA.
CVE736
Últimos 12 meses0
Críticas263
Explotadas activamente2
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2021-1906 | Media (5.5) | 0.52% | ⚠ Explotación activa | 7 may 2021 | Improper handling of address deregistration on failure can lead to new GPU address allocation failure. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT,… |
| CVE-2021-1905 | Alta (7.8) | 1.5% | ⚠ Explotación activa | 7 may 2021 | Possible use after free due to improper handling of memory mapping of multiple processes simultaneously. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2018-5852 | Alta (7.8) | 0.12% | — | 26 nov 2024 | An unsigned integer underflow vulnerability in IPA driver result into a buffer over-read while reading NAT entry using debugfs command 'cat /sys/kernel/debug/ipa/ip4_nat' |
| CVE-2018-11952 | Alta (7.8) | 0.11% | — | 26 nov 2024 | An image with a version lower than the fuse version may potentially be booted lead to improper authentication. |
| CVE-2018-11922 | Media (5.5) | 0.23% | — | 26 nov 2024 | Wrong configuration in Touch Pal application can collect user behavior data without awareness by the user. |
| CVE-2017-15832 | Alta (7.8) | 0.12% | — | 26 nov 2024 | Buffer overwrite in the WLAN host driver by leveraging a compromised WLAN FW |
| CVE-2016-10394 | Alta (7.8) | 0.10% | — | 26 nov 2024 | Initial xbl_sec revision does not have all the debug policy features and critical checks. |
| CVE-2017-9711 | Alta (7.8) | 0.12% | — | 22 nov 2024 | Certain unprivileged processes are able to perform IOCTL calls. |
| CVE-2023-21626 | Alta (7.1) | 0.11% | — | 8 ago 2023 | Cryptographic issue in HLOS due to improper authentication while performing key velocity checks using more than one key. |
| CVE-2022-40510 | Crítica (9.8) | 0.43% | — | 8 ago 2023 | Memory corruption due to buffer copy without checking size of input in Audio while voice call with EVS vocoder. |
| CVE-2022-40537 | Crítica (9.8) | 0.36% | — | 10 mar 2023 | Memory corruption in Bluetooth HOST while processing the AVRC_PDU_GET_PLAYER_APP_VALUE_TEXT AVRCP response. |
| CVE-2022-40531 | Alta (7.8) | 0.12% | — | 10 mar 2023 | Memory corruption in WLAN due to incorrect type cast while sending WMI_SCAN_SCH_PRIO_TBL_CMDID message. |
| CVE-2022-40515 | Crítica (9.8) | 0.33% | — | 10 mar 2023 | Memory corruption in Video due to double free while playing 3gp clip with invalid metadata atoms. |
| CVE-2022-33213 | Alta (8.8) | 0.41% | — | 10 mar 2023 | Memory corruption in modem due to buffer overflow while processing a PPP packet |
| CVE-2022-25705 | Alta (7.8) | 0.13% | — | 10 mar 2023 | Memory corruption in modem due to integer overflow to buffer overflow while handling APDU response |
| CVE-2022-25694 | Alta (7.8) | 0.12% | — | 10 mar 2023 | Memory corruption in Modem due to usage of Out-of-range pointer offset in UIM |
| CVE-2022-25655 | Alta (7.8) | 0.12% | — | 10 mar 2023 | Memory corruption in WLAN HAL while arbitrary value is passed in WMI UTF command payload. |
| CVE-2022-22075 | Media (5.5) | 0.12% | — | 10 mar 2023 | Information Disclosure in Graphics during GPU context switch. |
| CVE-2022-40512 | Alta (7.5) | 0.42% | — | 12 feb 2023 | Transient DOS in WLAN Firmware due to buffer over-read while processing probe response or beacon. |
| CVE-2022-33233 | Alta (7.8) | 0.12% | — | 12 feb 2023 | Memory corruption due to configuration weakness in modem wile sending command to write protected files. |
| CVE-2022-33229 | Alta (7.5) | 0.38% | — | 12 feb 2023 | Information disclosure due to buffer over-read in Modem while using static array to process IPv4 packets. |
| CVE-2022-25738 | Alta (7.5) | 0.38% | — | 12 feb 2023 | Information disclosure in modem due to buffer over-red while performing checksum of packet received |
| CVE-2022-25735 | Alta (7.5) | 0.41% | — | 12 feb 2023 | Denial of service in modem due to missing null check while processing TCP or UDP packets from server |
| CVE-2022-25734 | Alta (7.5) | 0.41% | — | 12 feb 2023 | Denial of service in modem due to missing null check while processing IP packets with padding |
| CVE-2022-25733 | Alta (7.5) | 0.41% | — | 12 feb 2023 | Denial of service in modem due to null pointer dereference while processing DNS packets |
| CVE-2022-25732 | Alta (7.5) | 0.38% | — | 12 feb 2023 | Information disclosure in modem due to buffer over read in dns client due to missing length check |
| CVE-2022-25728 | Alta (7.5) | 0.38% | — | 12 feb 2023 | Information disclosure in modem due to buffer over-read while processing response from DNS server |
| CVE-2022-33299 | Alta (7.5) | 0.38% | — | 9 ene 2023 | Transient DOS due to null pointer dereference in Bluetooth HOST while receiving an attribute protocol PDU with zero length data. |
| CVE-2022-33290 | Alta (7.5) | 0.38% | — | 9 ene 2023 | Transient DOS in Bluetooth HOST due to null pointer dereference when a mismatched argument is passed. |
| CVE-2022-33286 | Media (6.5) | 0.38% | — | 9 ene 2023 | Transient DOS due to buffer over-read in WLAN while processing 802.11 management frames. |
| CVE-2022-33285 | Media (6.5) | 0.38% | — | 9 ene 2023 | Transient DOS due to buffer over-read in WLAN while parsing WLAN CSA action frames. |
| CVE-2022-33266 | Alta (7.8) | 0.11% | — | 9 ene 2023 | Memory corruption in Audio due to integer overflow to buffer overflow while music playback of clips like amr,evrc,qcelp with modified content. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.